GK200 Graykey Examinations
GK200 is an intermediate-level four-day training course, designed for participants who are already familiar with the principles of computer forensics and are looking to expand their knowledge in the analysis of iOS and Android devices using Magnet Graykey.
Students must belong to a law enforcement agency and have prior authorization to attend the course.
Description
GK200 is an intermediate-level training course, lasting four days, designed for participants who are already familiar with the principles of computer forensics and are looking to expand their knowledge in the analysis of iOS and Android devices using Magnet Graykey. Students must belong to a law enforcement agency and have prior authorization to attend the course.
In this course, participants will get hands-on practice with the Graykey device and learn to operate it fully, including how to establish an appropriate workflow for handling iOS and Android devices both in the field and in the lab, and how to leverage Graykey to obtain crucial data from mobile devices.
Magnet Axiom will also be used to understand how mobile file systems are structured and how to locate key data. In addition, students will learn about specific artifacts from extractions performed with Magnet Graykey and the different levels of data protection implemented in modern mobile devices. From handling Keychain and Keystores, to advanced methodologies for discovering operating system artifacts, students will learn to treat data coming from mobile devices effectively and efficiently, regardless of the extraction level or device state.
Students must belong to a law enforcement agency and must possess a Magnet Graykey device.
What to expect
Hear directly from Justin Almanza, Forensic Instructor at Magnet Forensics, talk about the Magnet Forensics training courses designed specifically to help you in your mobile investigations, including Core Mobile Acquisition & Analysis (AX150), Axiom Advanced Mobile Forensics (AX300) and Graykey Examinations (GK200).
Course Requirements
Because GK200 is an intermediate-level course, it is recommended that students first complete Magnet Axiom Examinations (AX200).
Course Modules
Module 1: Course Introduction
Coverage of the basic requirements of both the Axiom software and the Graykey device.
Module 2: iOS Fundamentals
Analysis and discussion of iOS operating system security features and structure.
You will learn about the device's protection class keys, lock codes and their function, as well as other aspects of the operating system.
Module 3: Android Fundamentals
Coverage and analysis of Android operating system security features and structure.
You will learn about Android kernel structure, device encryption, and lock codes, as well as other general system functions.
Module 4: Graykey Overview
This module covers all the options and settings of the Graykey device and how to leverage them to operate the device successfully and efficiently in extracting information from mobile devices.
Module 5: iOS Acquisitions with Graykey
Understand the different workflows Graykey offers to extract data from iOS/iPadOS devices.
Learn to use Graykey to access data from locked iOS devices and apply methodologies to bypass security and access codes.
Module 6: Android Acquisitions with Graykey
Learn the different workflows Graykey offers to extract data from Android devices.
Understand Android market fragmentation and how to approach device examinations regardless of version or manufacturer.
Learn to use Graykey to access data on locked Android devices and apply techniques to overcome security and access codes.
Module 7: Anti-forensics on Android
Learn about the various methodologies that can be applied in an anti-forensic environment.
Learn about operating systems and applications that can be enabled to erase device data.
Understand the different impacts anti-forensic techniques can have on the examination of Android devices, from seizure and handling to extraction, analysis, and manual verification.
Module 8: Additional Graykey Features
Understand and learn to use additional Graykey features, such as Logical+, category-based extractions, Mobile Excursion and Magnet Graykey Fastrak.
Module 9: Graykey Outputs and Magnet Axiom
Understand the different types of output Graykey generates, depending on device state, and how to analyze the data they contain.
Learn to interpret information coming from key files such as Keychain and Keystore, and how Magnet Axiom can use these files to access data from secure and advanced applications.
Learn to process Graykey outputs efficiently within Axiom.
Explore Axiom features such as Dynamic App Finder and custom search by file type.
Module 10: Additional Password Recovery Methods
Learn to leverage mobile device data to achieve more effective password recovery.
Understand and learn to use tools such as Magnet Wordlist Generator to maximize password recovery potential.
Module 11: Analysis of iOS Extraction Types
Understand the main differences between BFU, AFU, Full File System and Logical+ extractions of iOS/iPadOS devices.
Learn to use Magnet Axiom to obtain the maximum possible evidence and information.
Learn additional data analysis techniques not usually found in the most common extraction types.
Module 12: Analysis of Android Extraction Types
Learn what information can be obtained from Android devices in different states.
Understand how to analyze data protection features such as Secure Folder and Dual Messenger.
Additional Information
Target audience: Participants with prior experience in computer forensics principles.
Prior preparation: None.
Program Level: Advanced.
Area of study: Software and computer applications.
Delivery method: In-person group.